cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #cybersecurity

[?]Dumb Password Rules » 🤖 🌐
@dumbpasswordrules@infosec.exchange

This dumb password rule is from Telekom/T-Systems MyWorkplace.

Telekom's MyWorkplace is a Single Sign On / login hub for their
Open Telekom Cloud which is basically an Amazon AWS clone. It's
rather new and especially for business customers. Especially
because it is for business customers, there's absolutely no reason
to limit a password to 16 characters. Eve...

dumbpasswordrules.com/sites/te

    [?]Dumb Password Rules » 🤖 🌐
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from SAS Eurobonus.

    The best thing about rules, is that you can multiple different ones!
    Like SAS that allows you to have a long password at least when signing
    up, but you'll be sorry if you want to change your password later on.

    dumbpasswordrules.com/sites/sa

      [?]Dumb Password Rules » 🤖 🌐
      @dumbpasswordrules@infosec.exchange

      This dumb password rule is from HSA Bank.

      - Must be minimum 12 characters
      - Must not be one of user's past 5 passwords
      - Must contain uppercase and lowercase letters
      - Must contain a number
      - Must not be the same as user's account number or login/username

      But also...
      - Cannot be longer than 20 characters

      dumbpasswordrules.com/sites/hs

        [?]Dumb Password Rules » 🤖 🌐
        @dumbpasswordrules@infosec.exchange

        Terence Eden boosted

        [?]Terence Eden [He/Him/♂/男] » 🌐
        @Edent@mastodon.social

        🆕 blog! “Cybersecurity for the paranoid business traveller”

        Over the years, I've worked for organisations with various levels of risk tolerance for business travellers. Some have been (rightly) paranoid and others have been (wrongly) placid about the threats their employees face.

        The fact is, individuals are often targeted for espionage, blackmail, or other…

        👀 Read more: shkspr.mobi/blog/2026/06/cyber

          [?]Dumb Password Rules » 🤖 🌐
          @dumbpasswordrules@infosec.exchange

          This dumb password rule is from Getin Bank.

          The new password should contain at least 10 and a maximum of 20 characters.
          The password must contain at least one upper case letter, one lower case
          letter and one number. The password cannot contain non-ASCII Polish alphabet
          characters, special characters `&<'"` or spaces.

          dumbpasswordrules.com/sites/ge

            [?]Dumb Password Rules » 🤖 🌐
            @dumbpasswordrules@infosec.exchange

            This dumb password rule is from Ameli.fr (French national health insurance).

            This was very painful to find a password that works with this one and that I can actually remember (I ended-up using my bank-account number because everything else failed). It took me maybe one hour and I thought I would become crazy (and yes, the session expires frequently while you are actually...

            dumbpasswordrules.com/sites/am

              [?]Dumb Password Rules » 🤖 🌐
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from Irodoricomics.

              A website to buy english-localized doujins. The password must be between 4 and 20 characters long

              dumbpasswordrules.com/sites/ir

                [?]Dumb Password Rules » 🤖 🌐
                @dumbpasswordrules@infosec.exchange

                This dumb password rule is from NetworkRail Open Data Feeds.

                Does require special characters but limits password length to 20.

                dumbpasswordrules.com/sites/ne

                  [?]Dumb Password Rules » 🤖 🌐
                  @dumbpasswordrules@infosec.exchange

                  This dumb password rule is from Replit.

                  Forces to use minimum 8 characters in the password and it must contain at least one uppercase.

                  dumbpasswordrules.com/sites/re

                    [?]Dumb Password Rules » 🤖 🌐
                    @dumbpasswordrules@infosec.exchange

                    This dumb password rule is from Lenovo.

                    - **Between 8 and 20 characters, not more.**
                    - 1 alphabetic letter
                    - 1 number (0-9)
                    - **1 symbol ($!#&)**

                    dumbpasswordrules.com/sites/le

                      Mike Cox boosted

                      [?]Open Rights Group » 🌐
                      @openrightsgroup@social.openrightsgroup.org

                      VPNs can help protect children's security online too. They aren’t just used to avoid content blocks.

                      Restrictions will deter people from using a core cybersecurity tool and create greater risks.

                      Privacy is online safety ✊️

                      Sign the petition to in the UK ➡️ action.openrightsgroup.org/tel

                      Image of a mobile phone held in a pair of hands with the thumbs over the screen with a neon effects in blue and purple.

Text: Sign the petition – Protect VPN use in the UK.

https://action.openrightsgroup.org/tell-government-protect-vpn-use-uk

                      Alt...Image of a mobile phone held in a pair of hands with the thumbs over the screen with a neon effects in blue and purple. Text: Sign the petition – Protect VPN use in the UK. https://action.openrightsgroup.org/tell-government-protect-vpn-use-uk

                        Kestral boosted

                        [?]Open Rights Group » 🌐
                        @openrightsgroup@social.openrightsgroup.org

                        The only way to create an ironclad age verification system in the UK is extreme digital authoritarianism.

                        Restrictions on VPNs are an attack on the open Internet and our ability to be secure online – the antithesis of online safety.

                        Read our briefing ➡️ openrightsgroup.org/publicatio

                        The only way to restrict VPNs is authoritarian.

Trying to ban or age-gate VPNs because they might be used to bypass digital ID age checks would be as unworkable as banning web browsers because they allow access to adult content.

Attempts to have a perfect age verification system that no-one can get around would involve an extreme level of digital authoritarianism.

To comprehensively prevent circumvention of age checks, a State would need to remove the ability of users to install and use software on their computer and try to prevent the Internet from providing open connectivity.

The government must not blow up our cybersecurity and the open Internet with technologically illiterate and authoritarian attacks on VPN use.

                        Alt...The only way to restrict VPNs is authoritarian. Trying to ban or age-gate VPNs because they might be used to bypass digital ID age checks would be as unworkable as banning web browsers because they allow access to adult content. Attempts to have a perfect age verification system that no-one can get around would involve an extreme level of digital authoritarianism. To comprehensively prevent circumvention of age checks, a State would need to remove the ability of users to install and use software on their computer and try to prevent the Internet from providing open connectivity. The government must not blow up our cybersecurity and the open Internet with technologically illiterate and authoritarian attacks on VPN use.

                          Mike Cox boosted

                          [?]Open Rights Group » 🌐
                          @openrightsgroup@social.openrightsgroup.org

                          Aside from restrictions, it's been suggested that sites should detect VPN use and bounce users into age verification.

                          This would be technically flawed, privacy-invasive and would exclude lawful Internet users because VPN traffic can look identical to ordinary encrypted web traffic.

                          Read our briefing ➡️ openrightsgroup.org/publicatio

                          Requiring sites to detect VPNs won't work.

The Age Verification Providers Association propose that sites age-gating content should detect VPN use and direct it to their services.

Technical infeasibility – Detection relies on blacklists of commercial VPN servers, which are incomplete and easily outpaced by new services.

False positives and exclusion – It would prevent law-abiding users, such as remote workers, people in high-risk environments, or families securing their Internet connection from getting online.

Privacy risks – This would require intrusive traffic analysis, undermining privacy and data protection.

Creating diplomatic rows – Users in countries that don't have age restrictions would also be caught up in it.

                          Alt...Requiring sites to detect VPNs won't work. The Age Verification Providers Association propose that sites age-gating content should detect VPN use and direct it to their services. Technical infeasibility – Detection relies on blacklists of commercial VPN servers, which are incomplete and easily outpaced by new services. False positives and exclusion – It would prevent law-abiding users, such as remote workers, people in high-risk environments, or families securing their Internet connection from getting online. Privacy risks – This would require intrusive traffic analysis, undermining privacy and data protection. Creating diplomatic rows – Users in countries that don't have age restrictions would also be caught up in it.

                            Mike Cox boosted

                            [?]Open Rights Group » 🌐
                            @openrightsgroup@social.openrightsgroup.org

                            Banning or blocking VPNs in the UK will shatter cybersecurity in a self-defeating attempt to make the unworkable workable.

                            Creating uncertainty around core Internet infrastructure could undermine the UK’s credibility as a stable place for digital businesses and security innovation.

                            Read our briefing ➡️ openrightsgroup.org/publicatio

                            Restricting VPNs is almost impossible.

DIY VPNs – Anyone can create a VPN on widely available cloud servers. This ability is built directly into the Linux OS and many consumer routers. Private, self-hosted VPNs can't be feasibly tracked or blocked.

Integration with operating systems – VPN functionality is a standard feature of Linux, Windows, macOS, iOS and Android.
Blocking or regulating it would require restricting core Internet protocols, with catastrophic knock-on effects for business and personal security.

Global nature of the Internet – Users will be driven to offshore providers, which would create compliance headaches for businesses, while leaving determined individuals unaffected by domestic restrictions on VPN use.

                            Alt...Restricting VPNs is almost impossible. DIY VPNs – Anyone can create a VPN on widely available cloud servers. This ability is built directly into the Linux OS and many consumer routers. Private, self-hosted VPNs can't be feasibly tracked or blocked. Integration with operating systems – VPN functionality is a standard feature of Linux, Windows, macOS, iOS and Android. Blocking or regulating it would require restricting core Internet protocols, with catastrophic knock-on effects for business and personal security. Global nature of the Internet – Users will be driven to offshore providers, which would create compliance headaches for businesses, while leaving determined individuals unaffected by domestic restrictions on VPN use.

                              Mike Cox boosted

                              [?]Open Rights Group » 🌐
                              @openrightsgroup@social.openrightsgroup.org

                              VPNs aren’t a meaningful threat to age verification measures.

                              ⚫ 6-12 year olds are very unlikely to use them due to technological and economic barriers.

                              ⚫ Older teens already know other workarounds.

                              Banning or restricting VPNs in the UK is overreach. The price is our privacy and security.

                              Read our briefing ➡️ openrightsgroup.org/publicatio

                              VPNs are unlikely to be used by 6-12 year olds.
Younger users
6-12 year olds are the focus of bringing in online safety' measures like age verification.
But they face significant barriers to VPN use.
The majority in this group are highly unlikely to download, configure or subscribe to VPNs without adult help. Especially if parental controls on app store downloads are enabled.
Adolescents and tech savvy teens
Those with the capacity to use VPNs are likely to be teens around 13-18 years old.
This group already have the skills and determination to use other workarounds to age checks (e.g. proxy sites, Tor, P2P sharing or borrowed account credentials).
VPN use is not a meaningful threat to the effectiveness of age verification, so restrictions are wholly unjustified.

                              Alt...VPNs are unlikely to be used by 6-12 year olds. Younger users 6-12 year olds are the focus of bringing in online safety' measures like age verification. But they face significant barriers to VPN use. The majority in this group are highly unlikely to download, configure or subscribe to VPNs without adult help. Especially if parental controls on app store downloads are enabled. Adolescents and tech savvy teens Those with the capacity to use VPNs are likely to be teens around 13-18 years old. This group already have the skills and determination to use other workarounds to age checks (e.g. proxy sites, Tor, P2P sharing or borrowed account credentials). VPN use is not a meaningful threat to the effectiveness of age verification, so restrictions are wholly unjustified.

                                [?]Open Rights Group » 🌐
                                @openrightsgroup@social.openrightsgroup.org

                                An adult using a VPN doesn't impact the safety of a child online.

                                Adults use VPNs because they don’t trust age verification providers with their personal data.

                                Something the UK government has refused to deal with by regulating the industry to ensure high standards of data protection.

                                Read more ➡️ openrightsgroup.org/publicatio

                                Why are more adults turning to VPNs?
The increase in VPN downloads suggests the public are wary of sharing their personal information with age verification providers.

That's because the industry is unregulated and companies are based in other countries that may have weaker data protection laws.

Also, the data gathered from ID checks can end up being repurposed for uses such as targeted advertising.

Asking adults to hand over highly sensitive ID documents or biometric data to unfamiliar companies goes against many years of cybersecurity advice around being careful when handing over personal data online.

Despite calls from ORG for age verification providers to be regulated, the government has done nothing except expand digital ID age checks into more areas of the Internet.

                                Alt...Why are more adults turning to VPNs? The increase in VPN downloads suggests the public are wary of sharing their personal information with age verification providers. That's because the industry is unregulated and companies are based in other countries that may have weaker data protection laws. Also, the data gathered from ID checks can end up being repurposed for uses such as targeted advertising. Asking adults to hand over highly sensitive ID documents or biometric data to unfamiliar companies goes against many years of cybersecurity advice around being careful when handing over personal data online. Despite calls from ORG for age verification providers to be regulated, the government has done nothing except expand digital ID age checks into more areas of the Internet.

                                  [?]Open Rights Group » 🌐
                                  @openrightsgroup@social.openrightsgroup.org

                                  Treating VPNs as a 'problem' is foolish.

                                  They help parents manage online risks, support secure remote working, protect people in abusive situations, and provide a lifeline to people in repressive States.

                                  UK MPs themselves use them!

                                  Attacking VPNs throws the baby out with the bath water.

                                  Read our briefing ➡️ openrightsgroup.org/publicatio

                                  What are Virtual Private Networks (VPNs)?

With a VPN, people can get on the Internet via a secure, encrypted connection to a remote server.

Cybersecurity and data privacy – VPNs mask your IP address to help prevent data tracking and unauthorised access, protecting users from data theft, DDoS attacks, identity fraud and surveillance.

This is important when using public WiFi or remote working and some VPN services are bundled with parental filters to restrict harmful websites at the network level.

Free expression – In places like Russia and China, VPNs let people access news, social media and resources blocked by governments.

This far outweighs the narrow concern that VPNs could be used to bypass age checks.

                                  Alt...What are Virtual Private Networks (VPNs)? With a VPN, people can get on the Internet via a secure, encrypted connection to a remote server. Cybersecurity and data privacy – VPNs mask your IP address to help prevent data tracking and unauthorised access, protecting users from data theft, DDoS attacks, identity fraud and surveillance. This is important when using public WiFi or remote working and some VPN services are bundled with parental filters to restrict harmful websites at the network level. Free expression – In places like Russia and China, VPNs let people access news, social media and resources blocked by governments. This far outweighs the narrow concern that VPNs could be used to bypass age checks.

                                    Melissa Fehr boosted

                                    [?]Open Rights Group » 🌐
                                    @openrightsgroup@social.openrightsgroup.org

                                    The UK government could announce restrictions on VPNs next month.

                                    This would threaten our privacy and security.

                                    VPNs keep young people safe from harassment. Businesses secure. Journalists, activists and whistleblowers protected.

                                    Here's why we must 🧵

                                    Sign the petition if you agree ⬇️

                                    action.openrightsgroup.org/tel

                                      Karl Baron boosted

                                      [?]jbz » 🌐
                                      @jbz@indieweb.social

                                      :tux: Thx to AI Linux will soon stop being a platform for retrocomputing hardware. Old hw support is getting deprecated to reduce the attack surface.

                                      Meanwhile the Linux Foundation is creating its nth AI/crypto related group.

                                        [?]Dumb Password Rules » 🤖 🌐
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from California Department of Motor Vehicles.

                                        They also prohibit pasting into the password field by using a JavaScript
                                        `alert()` whenever you right-click or press the `Ctrl` button, so
                                        you can't use a password manager.

                                        dumbpasswordrules.com/sites/ca

                                          [?]Dumb Password Rules » 🤖 🌐
                                          @dumbpasswordrules@infosec.exchange

                                          This dumb password rule is from Ancestry.

                                          Password:
                                          - Must be at least 8 characters long
                                          - Must contain at least 1 number
                                          - Must contain at least 1 letter or special character
                                          - Must not be a well known or common password

                                          dumbpasswordrules.com/sites/an

                                            [?]Open Rights Group » 🌐
                                            @openrightsgroup@social.openrightsgroup.org

                                            VPNs help people stay safe and secure online.

                                            If adults use them to by-pass ID checks, it's because they don't trust unregulated age verification providers with their data.

                                            We mustn't bulldoze cybersecurity with another authoritarian attack on the open Internet.

                                            Sign the petition in the UK ⬇️

                                            action.openrightsgroup.org/tel

                                              Wen boosted

                                              [?]Open Rights Group » 🌐
                                              @openrightsgroup@social.openrightsgroup.org

                                              🚨 First the social media ban, now the UK government wants to restrict VPNs 🚨

                                              VPNs are a vital cybersecurity tool for businesses, politicians, journalists and families to protect data and communications.

                                              Banning or requiring digital ID checks before buying VPNs would increase cybercrime risks and expose IP addresses to predators.

                                              express.co.uk/news/uk/2217934/

                                                [?]Dumb Password Rules » 🤖 🌐
                                                @dumbpasswordrules@infosec.exchange

                                                This dumb password rule is from ANZ Bank.

                                                Your password needs to be between 8 and 16 characters long - no special characters allowed.

                                                dumbpasswordrules.com/sites/an

                                                  [?]Dumb Password Rules » 🤖 🌐
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from Daybreak Games.

                                                  Max password length is 15 characters

                                                  The only special characters that can be used are !"#$%

                                                  dumbpasswordrules.com/sites/da

                                                    [?]Dumb Password Rules » 🤖 🌐
                                                    @dumbpasswordrules@infosec.exchange

                                                    This dumb password rule is from Credit Agricole.

                                                    * Login is a predefined 11 digits long identifier that you can not change
                                                    * Password is a 6 digits long identifier that you need to input using your mouse

                                                    dumbpasswordrules.com/sites/cr

                                                      [?]Dissent Doe :cupofcoffee: [She/Her] » 🌐
                                                      @PogoWasRight@infosec.exchange

                                                      NEW by me:

                                                      One threat actor demanded $50 million from Novo Nordisk. Another one demanded $25 million. Neither got paid.

                                                      Two different groups tried to extort Novo Nordisk at around the same time. Novo Nordisk strung them both along, and then went dark.

                                                      Data leaks followed.

                                                      databreaches.net/2026/06/16/on

                                                      @campuscodi @euroinfosec @jgreig @lorenzofb @ajvicens @amvinfe

                                                        [?]BobDaHacker 🏳️‍⚧️ [She/They] » 🌐
                                                        @bobdahacker@infosec.exchange

                                                        ✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.

                                                        Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.

                                                        Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.

                                                        Full writeup: bobdahacker.com/blog/frontier-

                                                          Tim Hergert boosted

                                                          [?]Pete Orrall [Pete/Pete] » 🌐
                                                          @peteorrall@mastodon.bsd.cafe

                                                          [?]Dumb Password Rules » 🤖 🌐
                                                          @dumbpasswordrules@infosec.exchange

                                                          This dumb password rule is from Parnassus Investments.

                                                          A site responsible for protecting your investments limiting you to a
                                                          four character range with a bunch of other stupid rules? Shocking.

                                                          dumbpasswordrules.com/sites/pa

                                                            [?]Mysk🇨🇦🇩🇪 » 🌐
                                                            @mysk@mastodon.social

                                                            Using Loupe, we found out that Proton VPN is the only VPN that prevents internal tunnel IP fingerprinting by assigning 10.2.0.2 to all users. Other VPNs, such as Mullvad, assign a static and unique IP per session. This allows iOS apps to track user sessions across apps.

                                                            Mullvad is aware of this issue. It is described in this blog:

                                                            mullvad.net/en/help/why-wiregu

                                                            You can download Loupe here:
                                                            apps.apple.com/app/id6766152470

                                                            Proton VPN tunnel internal IP as shown in the Settings app

                                                            Alt...Proton VPN tunnel internal IP as shown in the Settings app

                                                            Proton VPN tunnel internal IP as shown in Loupe

                                                            Alt...Proton VPN tunnel internal IP as shown in Loupe

                                                            Mullvad VPN tunnel internal IPs as shown in the Settings app

                                                            Alt...Mullvad VPN tunnel internal IPs as shown in the Settings app

                                                            Mullvad VPN tunnel internal IPs as shown in Loupe

                                                            Alt...Mullvad VPN tunnel internal IPs as shown in Loupe

                                                              [?]Dumb Password Rules » 🤖 🌐
                                                              @dumbpasswordrules@infosec.exchange

                                                              This dumb password rule is from MKB NetBankár.

                                                              It only accepts lowercase letters, uppercase letters and numbers (any
                                                              other character counts as forbidden character).
                                                              Also, if your password contains any invalid character, it will get
                                                              marked as "Identical to the former 10 passwords".

                                                              To make it more fun, during the registration, it allows to se...

                                                              dumbpasswordrules.com/sites/mk

                                                                [?]BobDaHacker 🏳️‍⚧️ [She/They] » 🌐
                                                                @bobdahacker@infosec.exchange

                                                                ⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.

                                                                Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide.

                                                                Full writeup: bobdahacker.com/blog/fifa-hack

                                                                  [?]Dumb Password Rules » 🤖 🌐
                                                                  @dumbpasswordrules@infosec.exchange

                                                                  This dumb password rule is from INSS (Instituto Nacional do Seguro Social).

                                                                  The National Social Security Institute (INSS) is an autarchy of the Government of Brazil linked to the Ministry of Economy that receives the contributions for the maintenance of the General Social Security System, responsible for the payment of pensions, maternity pay, death pay, sickness pay, ac...

                                                                  dumbpasswordrules.com/sites/in

                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from WellStar MyChart.

                                                                    Your password must be between 8 and 20 characters.

                                                                    dumbpasswordrules.com/sites/we

                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from Broadcom.

                                                                      - Between 8 and 50 characters
                                                                      - Can't contain any substring of length 3 or more from your email address.
                                                                      - At least 1 uppercase letter, lowercase letter, and digit, and special character.
                                                                      - Oh right, to really mess with password managers: no more than 10 special characters and pasting into the pa...

                                                                      dumbpasswordrules.com/sites/br

                                                                        [?]Dumb Password Rules » 🤖 🌐
                                                                        @dumbpasswordrules@infosec.exchange

                                                                        This dumb password rule is from Afraid.org FreeDNS.

                                                                        Password must be between 4 and 16 characters long

                                                                        dumbpasswordrules.com/sites/af

                                                                          [?]Anthropy » 🌐
                                                                          @anthropy@mastodon.derg.nz

                                                                          Arch users PSA: discourse.ifin.network/t/400-a

                                                                          1600+ AUR packages have been compromised with infostealers and rootkits.

                                                                          If you've recently deployed AUR packages, please check your system if you're affected, potentially reinstall and cycle your passwords if that's the case.

                                                                          this doc seems to keep the full list up to date: md.archlinux.org/s/SxbqukK6IA

                                                                          backup: nextcloud.dragonhive.net/s/dXN

                                                                            [?]Dumb Password Rules » 🤖 🌐
                                                                            @dumbpasswordrules@infosec.exchange

                                                                            This dumb password rule is from PCPartPicker.

                                                                            There are no rules for passwords. Passwords can be any length (including one character)
                                                                            of any complexity. No password change confirmation emails are sent.

                                                                            dumbpasswordrules.com/sites/pc

                                                                              [?]Dumb Password Rules » 🤖 🌐
                                                                              @dumbpasswordrules@infosec.exchange

                                                                              This dumb password rule is from Copyright.gov.

                                                                              I wonder if they cooperate with NSA to enforce the password rules.

                                                                              dumbpasswordrules.com/sites/co

                                                                                [?]BrianKrebs » 🌐
                                                                                @briankrebs@infosec.exchange

                                                                                The Senate Judiciary Committee chairman is demanding answers from CISA about an alarming data exposure incident wherein a contractor leaked oodles of internal CISA passwords -- including multiple AWS GovCloud credentials -- in a public GitHub profile for six months until notified by Yours Truly. The letter this week from Sen. Chuck Grassley (IA) is notable because he's the most senior lawmaker to inquire about this colossal screw up so far, and he's a Republican.

                                                                                grassley.senate.gov/imo/media/

                                                                                Original report on the CISA data exposure:
                                                                                krebsonsecurity.com/2026/05/ci

                                                                                Mr. Nicholas M. Andersen
Acting Director
Cybersecurity and Infrastructure Security Agency
Dear Acting Director Andersen:

On May 18, 2026, it was reported that a contractor-employee for the Cybersecurity &
Infrastructure Security Agency (CISA) maintained a public GitHub repository, a cloud-based platform used to store and share information for purposes of developing software code, that stored CISA credentials to several highly sensitive AWS GovCloud accounts and a large number of internal CISA systems, including passwords and cloud keys.1

The title of the public repository was reportedly “Private-CISA.”2
 Reports stated “a review of the GitHub account and
its exposed passwords show the ‘Private-CISA’ repository was maintained by an employee of Nightwing.”3
 
It was also reported the GitHub account that included the repository titled
“Private-CISA” was taken offline shortly after at least two cyber-security research companies notified CISA of the exposure, but the exposed AWS keys continued to remain valid for another 48 hours.4 CISA spokesperson Marco DiSandro said the agency is “aware of the reported exposure and is continuing to investigate the situation,” and that there is “no indication that any sensitive data was compromised as a result of this incident.”5

However, according to reports, CISA would not say if the agency has seen any evidence of a breach stemming from this exposure.

                                                                                Alt...Mr. Nicholas M. Andersen Acting Director Cybersecurity and Infrastructure Security Agency Dear Acting Director Andersen: On May 18, 2026, it was reported that a contractor-employee for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository, a cloud-based platform used to store and share information for purposes of developing software code, that stored CISA credentials to several highly sensitive AWS GovCloud accounts and a large number of internal CISA systems, including passwords and cloud keys.1 The title of the public repository was reportedly “Private-CISA.”2 Reports stated “a review of the GitHub account and its exposed passwords show the ‘Private-CISA’ repository was maintained by an employee of Nightwing.”3 It was also reported the GitHub account that included the repository titled “Private-CISA” was taken offline shortly after at least two cyber-security research companies notified CISA of the exposure, but the exposed AWS keys continued to remain valid for another 48 hours.4 CISA spokesperson Marco DiSandro said the agency is “aware of the reported exposure and is continuing to investigate the situation,” and that there is “no indication that any sensitive data was compromised as a result of this incident.”5 However, according to reports, CISA would not say if the agency has seen any evidence of a breach stemming from this exposure.

                                                                                  [?]Fedora Project » 🌐
                                                                                  @fedora@fosstodon.org

                                                                                  PSA regarding a change in how Secure Boot will work in Fedora soon. The change isn't urgent, but it is something you should take a look at.

                                                                                  If you have any questions about this, please ask in our forum. 🙏

                                                                                  ➡️ fedoramagazine.org/expiration-

                                                                                  Forum: discussion.fedoraproject.org/c

                                                                                    Back to top - More...